Beacon: Network Field Audit

Scan, audit, hand over a PDF

$4.99 · Designed for iPad. Not verified for macOS.

Every consulting engagement starts the same way: you walk into a building you have never seen and someone asks what is on this network, is any of it about to fall over, and where are the holes. Beacon answers that from your phone, and turns the visit into a document you can hand over before you leave. Nothing leaves the device. No account, no cloud, no analytics. The client's network map stays on your phone, which for a security conscious client is the entire procurement conversation. FIND EVERY DEVICE, INCLUDING THE QUIET ONES One tap sweeps the real subnet, derived from your interface netmask rather than assuming a /24, so a client on a /22 gets all of it. Beacon treats a refused connection as proof a host exists, reads the kernel neighbour table for devices that answer nothing at all, and browses Bonjour throughout. Firewalled and silent kit still lands in the device count, and the app tells you which devices were seen only at layer 2 instead of quietly dropping them. Plugged into the switch with a USB-C adapter instead of joining the wifi? Beacon scans that interface too. IDENTIFY WHAT EACH BOX ACTUALLY IS Vendor from the MAC, hostname from reverse DNS and Bonjour, open ports, advertised services, and a role guess for each host. Privacy randomised MAC addresses are named as such rather than shown as an unknown vendor, which is also why that device will not hold a DHCP reservation. AUDIT THE HOSTS THAT MATTER, READ ONLY TLS and certificates: expiry, weak protocol versions, self signed and untrusted chains, key strength, subject alternative names. SSH host audit: sign in with a key or password held in the Keychain behind Face ID, and Beacon runs one combined read only playbook. Operating system and end of life status, disk and memory headroom, listening sockets, running services, pending updates, sshd hardening, crypto algorithms, firewall state, failed login volume. It reads. It never installs, changes, starts or stops anything. Exposed services: Telnet, FTP, RDP, VNC, unauthenticated databases and caches, Docker APIs, building and industrial control ports on a flat corporate network. Web headers: HSTS, redirect to HTTPS, CSP, clickjacking and sniffing protection, server version disclosure. SNMP: whether the device answers the default community, and what it says about itself. Default credentials: identified from the device fingerprint, never by trying one. FINDINGS THAT SHOW THEIR WORKING Every finding carries the evidence line it came from, ranked by severity. When a check cannot run, Beacon says so rather than reporting a clean result. An auditor will not sign a black box, and a tool that quietly passes a host it never read is worse than no tool. THE DOCUMENT IS THE PRODUCT One tap turns the visit into a branded multi page PDF: site, client and technician on the cover, the device inventory, and every finding grouped by host with its evidence. That artefact is what the engagement is paid to produce. WHAT CHANGED SINCE LAST VISIT Save a site, come back next quarter, and Beacon diffs it. New devices, devices that fell off, ports that opened or closed. Scans are organised by client, then site, then dated visit, the way a consultant already thinks about the work. STRAIGHT ABOUT WHAT iOS ALLOWS iOS forbids raw sockets, so there is no ICMP ping, no ARP sweep and no packet capture, and Beacon does not pretend otherwise. It discovers by TCP connect, the neighbour table, Bonjour and reverse DNS, and it tells you plainly what a silent host can still hide. Handled honestly, the boundary is a credibility signal rather than a hidden failure. AUTHORISED USE ONLY Beacon is for networks you own or are contracted to assess. It is defensive and read only throughout. It never exploits, never brute forces and never attacks anything. iPhone and iPad. Buy once, no subscription.

  • This app hasn’t received enough ratings or reviews to display an overview.

This release is about the thing you hand the client. PROVE WHAT GOT FIXED Beacon now saves its findings with every scan, not just the devices it found. Return to a site and the report opens with what was resolved since your last visit, what is still open, and what is new. That page is the one that justifies the retainer, and until now the app could tell you a device had appeared but never that the expired certificate you reported in March is still expired. A POSTURE SCORE, TRENDED One number per visit, drawn across every visit to that site. It is 100 less 12 for each critical finding, 4 for each warning and 1 for each note, and that arithmetic is printed next to the number everywhere it appears. A score nobody can explain is a score nobody will defend in front of a client. A REPORT THAT OPENS WITH THE ANSWER The PDF now starts with a summary page: the score, the movement since last visit, and the three things to deal with first. The network map is drawn into the document, so the client finally sees the picture that was only ever on your screen. Findings are ordered by severity and each one names the machine it came from. YOUR NAME ON IT, NOT OURS Put your firm's name, logo, contact line and accent colour on the cover. The "Prepared with Beacon" line at the foot is a switch you can turn off. A report branded for the tool instead of the firm that charged for it gets retyped, not handed over. EXPORT FOR YOUR OWN SYSTEMS Device inventory as CSV, findings as CSV, and the whole scan as JSON. The PDF is for the client. The findings sheet is the one that becomes tickets. KNOW WHAT YOU ARE LOOKING AT The full IEEE vendor registry is now built in, around 40,000 prefixes, offline. Far fewer devices come back as an unknown MAC address, and the ones that never can be (modern phones use a different random address on every network) are labelled as exactly that instead of pretending to be a mystery. AN INVENTORY, NOT JUST A LIST Give a device a name, an asset tag, a location, an owner, a serial and a photo of the actual box in the actual rack. It is filed against the hardware, not the address, so it follows the device when DHCP moves it, and it is waiting for you on the next visit. DUE FOR ANOTHER LOOK Sites show how long it has been and when they are due again. Nobody carrying twenty clients remembers which one was last audited in March. Also in this release: saved scans can no longer be lost if the history file cannot be read, the app now refuses to write over anything it could not load, and the report no longer prints a section heading with its contents on the following page. Still read-only, still on the device. Beacon never tries a password, never changes a setting, and sends nothing to any cloud.

The developer, Matthew Mesropian, indicated that the app’s privacy practices may include handling of data as described below. For more information, see the developer’s privacy policy .

  • Data Not Collected

    The developer does not collect any data from this app.

    Privacy practices may vary, for example, based on the features you use or your age. Learn More

    The developer has not yet indicated which accessibility features this app supports. Learn More

    Seller
    • Matthew Mesropian
    Size
    • 9.6 MB
    Category
    • Utilities
    Compatibility
    Requires iOS 17.0 or later.
    • iPhone
      Requires iOS 17.0 or later.
    • iPad
      Requires iPadOS 17.0 or later.
    • Mac
      Requires macOS 14.0 or later and a Mac with Apple M1 chip or later.
    • Apple Vision
      Requires visionOS 1.0 or later.
    Languages
    • English
    Age Rating
    4+
    Copyright
    • © Integrated Software Technologies 2026